CVE-2026-107388
Awaiting Analysis Awaiting Analysis - Queue

ID3v2 Memory Allocation in music-metadata

Vulnerability report for CVE-2026-107388, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the EndOfStreamError is caught internally, and the caller receives a normal metadata object. This issue is fixed in version 11.16.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Borewit music-metadata < 11.16.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in music-metadata before 11.16.0 involves the ID3v2 parser trusting a tag-size field that can request large memory allocations. A truncated file with only an ID3v2 header can trigger an allocation of up to 268 MiB before verifying the input size. The parser then fails to read the expected data, but handles the error internally, returning normal metadata to the caller.

Detection Guidance

To detect this vulnerability, check if your system uses music-metadata library versions prior to 11.16.0. Use commands like 'npm list music-metadata' for Node.js or inspect package dependencies in your project files. For network-based detection, monitor for unusual memory usage spikes when processing media files, particularly those with ID3v2 tags.

Impact Analysis

This vulnerability could allow an attacker to cause a denial of service by consuming excessive memory on the system running the vulnerable version of music-metadata. It may lead to application crashes or slowdowns due to resource exhaustion.

Compliance Impact

This vulnerability primarily impacts system availability due to potential denial-of-service (DoS) conditions caused by memory exhaustion. While not directly violating GDPR or HIPAA, it could indirectly affect compliance by disrupting services handling personal or health data. GDPR requires ensuring data processing integrity and availability, while HIPAA mandates safeguards against service disruptions. Exploitation could lead to prolonged downtime, potentially violating these requirements.

Mitigation Strategies

Update music-metadata to version 11.16.0 or later to address the ID3v2 parser issue. Check applications using this library and ensure they are updated to avoid potential memory allocation issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107388. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart